@cthos Thanks for the feedback. Since it does appear that you can configure as required, I'm not sure this constitutes a bug. However if it is confusion to you it is likely to others as well. It may be worth opening an issue for the dev team to take a look at.
There's also another kind of spam that we're noticing. At least for Google IdP accounts, scammers are adjusting their name to include malicious URLs (without even using link tags). The gmail UI will unfortunately render them as links.
Does FA have some built-in functionality to deal with this scenario?